The package has a minimal dependency footprint, no install-time scripts, and a matching source repository. Its README is present, but there are no tests or security policy, leaving limited evidence for ongoing quality control.
38%
Total Score
0
100
71
75
Only one release exists, published more than 11 years ago, with no releases in the last 12 months. That strongly limits evidence of maintenance for a dependency taken today.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and a high abandonment risk.
The repository has only 4 stars, 5 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little compensating evidence for the maintenance concerns.
Composer is used for builds, but no security scanning tooling is present. Given the package's age and inactive repository, the missing automated security checks provide no compensating assurance.
No security policy was found in the repository, reducing transparency for reporting and handling vulnerabilities. This is a hygiene concern rather than a standalone reason to reject the package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.